—
GO-2022-0476
Arbitrary code execution via the go command with cgo in cmd/go
Quick fix
GO-2022-0476 — toolchain: upgrade to the fixed version with the command below.
go get toolchain@v1.14.12Details
The go command may execute arbitrary code at build time when cgo is in use. This may occur when running go get on a malicious package, or any other command that builds untrusted code.
This can be caused by malicious gcc flags specified via a cgo directive.
Are you affected?
Enter the version of the package you're using.